MITM Checker

Discussion in 'other anti-malware software' started by svenfaw, May 21, 2019.

  1. guest

    guest Guest

     
  2. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    thanks so I have a huge wall of alerts with kaspersky antivirus personal root certificate
    must be some compatibility stuff with KA free
     
  3. askmark

    askmark Registered Member

    Joined:
    Jul 7, 2016
    Posts:
    392
    Location:
    united kingdom
    It been renamed to NoSnoop. Although, the download link is not working at the moment until the author fixes it.
     
  4. guest

    guest Guest

    The download link for NoSnoop works now.
    https://www.trustprobe.com/fs1/download.php?appname=NoSnoop.zip
     
  5. Josh McCormick

    Josh McCormick Registered Member

    Joined:
    Nov 4, 2019
    Posts:
    1
    Location:
    USA
    Quite an interesting tool!

    I'm on Cox Internet.
    I had an alert on "huawei.com" and an occasional alert on "www.bbc.co.uk" (it is currently NOT alerting)

    www.bbc.co.uk 0 GlobalSign Root CA - R1 B1BC968BD4F49D622AA89A81F2150152A41D829C
    www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC​

    I switched to a third-party's VPN (which sees a random amount of handshake failures).
    The "huawei.com" detection remained, and I wasn't able to get an alert on "www.bbc.co.uk" (but I can't say if the lack of a BBC hit had any real meaning here or not).

    www.bbc.co.uk 0 GlobalSign Root CA - R1 B1BC968BD4F49D622AA89A81F2150152A41D829C
    www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC​

    Still, the alert on Huawei kind of raises an eyebrow, doesn't it?

    I noticed someone on Hacker News seeing similar results. If I want to investigate this further, what's my next step? Suggestions for Linux tools are especially welcome.

    Thanks all.
     
  6. HempOil

    HempOil Registered Member

    Joined:
    Jun 15, 2015
    Posts:
    225
    Location:
    Canada
    I also get the alert on huawei
     
  7. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344
    Clean your system. Save as .bat (like Clear.bat) and run

     
  8. Surt

    Surt Registered Member

    Joined:
    Jan 23, 2019
    Posts:
    471
    Location:
    USA
    The zip file used to contain a hostlist.txt; top100.txt when it was MTM Checker.

    One could whip up one's own hostlist.txt. Not any more.

    The previous nosnoop.exe was 152 KB and the current exe is 377 KB.

    Looks like the hosts are now "built in," as hostlist.txt is ignored. :(

    https://www.trustprobe.com/ as of this posting opens with:
    TrustProbe
    Seriously cool things coming soon!

    I hope so...
     
  9. ravenise

    ravenise Registered Member

    Joined:
    Jul 18, 2009
    Posts:
    92
    @svenfaw
    Tried it, but both versions don't even load in windows 10 1909 x64, or fresh windows 10 1909 x64 VM, or fresh windows 7 x64 VM, not sure whats up. No error message, or warnings or window period, just nothing.
     
  10. ravenise

    ravenise Registered Member

    Joined:
    Jul 18, 2009
    Posts:
    92
    Got it working finally, had to change the date to July 8 2019; works only temporarily after each release
     
  11. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
  13. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    so what are you supposed to do when you find Alerts ?
    Not visit those sites? :D

    nosnoop.jpg
     
    Last edited: Jul 8, 2020
  14. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Always ready to try something new. So, here goes.

    NoSnoop_Untrusted File_ SecureAPlus_01.JPG >>> NoSnoop_Untrusted File_ SecureAPlus_02.JPG
    >>> NoSnoop_Untrusted File_ SecureAPlus_03.JPG

    NoSnoop_Untrusted File_ SecureAPlus_04.JPG
     
  15. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    The AAA Certificate Services (D1EB23A46D17D68FD92564C2F1F1601764D8E349) alert is a false positive.

    Fixed in version 0.83.
     
  16. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Indeed. Thanks!
     
  17. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Any plans for a 32-bit version? Won't run on the system I'm currently on.
     
  18. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    All Good here!

    2020-07-09_19-55-12.png
     
  19. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,076
    Location:
    UK
    Doubleclick.net handshake failure n/a ?
     
  20. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    518
    Location:
    Bulgaria
    medlineplus.gov 0 Handshake failure
    The rest are all good.

    Anyway after re-scan all is ok now. :)
     
  21. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    On my to-do list :)
     
  22. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    A possible reason could be if you are using a system-wide adblocker, or have a doubleclick.net entry in your hosts file.
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Ha. That explains it, I had a quite a few 'handshake failure N/A', and disabling AdGuard for Windows solved that. Neat.

    Except for utorrent ...
    Don't use it so not sure why it's even there ...
     
  24. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    screenshot1.png


    New version: v0.87.003

    Some more specific host lists have been added:
    - Email services
    - Financial services
    - Communication services
     
  25. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Interesting additions. All fine on the home front with this new version :thumb:

    fd.jpg
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.